You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

oidc-client-ts无法返回完整Profile Claims问题求助

问题:oidc-client-ts 返回的 User Profile 字段缺失,与 oidc-client-js 差异显著

我使用 oidc-client-ts(TypeScript 版本)实例化 UserManager 时采用如下配置:

var config = {
  authority: "https://localhost:3000",
  client_id: "js",
  redirect_uri: "https://localhost:3001/callback.html",
  response_type: "code",
  scope: "openid profile IdentityServerApi colour", 
  post_logout_redirect_uri: "https://localhost:3001/index.html",
}

调用 usermanager.getUser() 返回的 user 对象,其 profile claims 仅包含以下字段:

{
  "iss": "https://localhost:3000",
  "iat": 1681658331,
  "exp": 1681658631,
  "aud": "js",
  "sid": "E5E4621779C8970433CEE2E6472FF8DE",
  "sub": "cc23a1a1-a8ff-4caf-8fef-555d98923b8a",
  "idp": "local"
}

但使用相同配置的 oidc-client-js 返回的 profile 包含更多字段:

{
  "amr": [
    "pwd"
  ],
  "sid": "32A90BF8B0EBF7780BC9B8E0AD3DDE8B",
  "sub": "cc23a1a1-a8ff-4caf-8fef-555d98923b8a",
  "auth_time": 1681659272,
  "idp": "local",
  "name": "theadmin@email.com",
  "preferred_username": "theadmin@email.com",
  "favorite_colour": "FAVORITECOLOUR_DEFAULT"
}

我尝试在配置中添加 client_authentication、loadUserInfo 等参数,但无效果。授权端点显示,使用 ts 模块时 userClaims 会被请求两次,而 js 模块会请求三次。客户端回调页的 UserManager 配置如下:

{
  authority: "https://localhost:3000", 
  response_mode: "query", 
  client_id: "js",
  redirect_uri: "https://localhost:3001/callback.html",
}

希望改用新版本的 ts 模块,但不清楚为何两者返回的 profile 数据差异如此之大,恳请指点。


排查思路与解决方案

1. 确保 loadUserInfo 参数全局生效

oidc-client-ts 与 oidc-client-js 的 loadUserInfo 默认值可能不同,需在主配置和回调页配置中都显式设置 loadUserInfo: true。回调页的 UserManager 处理授权响应时,同样需要触发 UserInfo 端点请求来获取完整用户数据。

2. 补全回调页的关键配置参数

当前回调页的 UserManager 缺少 response_type 和 scope,这会导致处理授权响应时无法正确触发后续流程。补全后配置如下:

{
  authority: "https://localhost:3000", 
  response_mode: "query", 
  client_id: "js",
  redirect_uri: "https://localhost:3001/callback.html",
  response_type: "code",
  scope: "openid profile IdentityServerApi colour",
  loadUserInfo: true
}

3. 验证 UserInfo 端点的返回内容

直接调用 IdentityServer 的 UserInfo 端点(GET {authority}/connect/userinfo,携带有效 Access Token),确认返回数据是否包含缺失的 name、favorite_colour 等字段。如果端点返回完整数据,但 ts 模块未合并,需检查 filterProtocolClaims 参数是否过滤了非标准 claims。

4. 检查授权请求的 Scope 传递情况

通过浏览器开发者工具查看授权跳转的 URL,确认 scope 参数确实包含 profile 和 colour。若 Scope 传递不完整,IdentityServer 不会返回对应的自定义 claims。

5. 注意两个库的行为差异

oidc-client-ts 作为 oidc-client-js 的重构版本,部分默认行为有变更:

  • 部分版本中 loadUserInfo 默认值为 false,而旧版 js 可能默认 true;
  • ts 版本中 user.profile 可能仅包含 ID Token 中的 claims,UserInfo 端点返回的数据需从 user.userInfo 属性单独获取,而非自动合并到 profile。

内容的提问来源于stack exchange,提问作者Joseph Hutton

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 22:32:46